CVE-2009-2813

Samba 3.4 before 3.4.2, 3.3 before 3.3.8, 3.2 before 3.2.15, and 3.0.12 through 3.0.36, as used in the SMB subsystem in Apple Mac OS X 10.5.8 when Windows File Sharing is enabled, Fedora 11, and other operating systems, does not properly handle errors in resolving pathnames, which allows remote authenticated users to bypass intended sharing restrictions, and read, create, or modify files, in certain circumstances involving user accounts that lack home directories.
References
Link Resource
http://lists.apple.com/archives/security-announce/2009/Sep/msg00004.html
http://lists.opensuse.org/opensuse-security-announce/2009-10/msg00004.html
http://marc.info/?l=bugtraq&m=126514298313071&w=2
http://marc.info/?l=bugtraq&m=126514298313071&w=2
http://news.samba.org/releases/3.0.37/
http://news.samba.org/releases/3.2.15/
http://news.samba.org/releases/3.3.8/
http://news.samba.org/releases/3.4.2/
http://osvdb.org/57955
http://secunia.com/advisories/36701 Vendor Advisory
http://secunia.com/advisories/36893 Vendor Advisory
http://secunia.com/advisories/36918 Vendor Advisory
http://secunia.com/advisories/36937 Vendor Advisory
http://secunia.com/advisories/36953 Vendor Advisory
http://secunia.com/advisories/37428 Vendor Advisory
http://slackware.com/security/viewer.php?l=slackware-security&y=2009&m=slackware-security.561439
http://sunsolve.sun.com/search/document.do?assetkey=1-77-1021111.1-1
http://support.apple.com/kb/HT3865 Vendor Advisory
http://wiki.rpath.com/Advisories:rPSA-2009-0145
http://www.samba.org/samba/security/CVE-2009-2813.html Vendor Advisory
http://www.securityfocus.com/archive/1/507856/100/0/threaded
http://www.securityfocus.com/bid/36363
http://www.ubuntu.com/usn/USN-839-1
http://www.vupen.com/english/advisories/2009/2810 Vendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/53174
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7211
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7257
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7791
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9191
https://www.redhat.com/archives/fedora-package-announce/2009-October/msg00095.html
https://www.redhat.com/archives/fedora-package-announce/2009-October/msg00098.html
http://lists.apple.com/archives/security-announce/2009/Sep/msg00004.html
http://lists.opensuse.org/opensuse-security-announce/2009-10/msg00004.html
http://marc.info/?l=bugtraq&m=126514298313071&w=2
http://marc.info/?l=bugtraq&m=126514298313071&w=2
http://news.samba.org/releases/3.0.37/
http://news.samba.org/releases/3.2.15/
http://news.samba.org/releases/3.3.8/
http://news.samba.org/releases/3.4.2/
http://osvdb.org/57955
http://secunia.com/advisories/36701 Vendor Advisory
http://secunia.com/advisories/36893 Vendor Advisory
http://secunia.com/advisories/36918 Vendor Advisory
http://secunia.com/advisories/36937 Vendor Advisory
http://secunia.com/advisories/36953 Vendor Advisory
http://secunia.com/advisories/37428 Vendor Advisory
http://slackware.com/security/viewer.php?l=slackware-security&y=2009&m=slackware-security.561439
http://sunsolve.sun.com/search/document.do?assetkey=1-77-1021111.1-1
http://support.apple.com/kb/HT3865 Vendor Advisory
http://wiki.rpath.com/Advisories:rPSA-2009-0145
http://www.samba.org/samba/security/CVE-2009-2813.html Vendor Advisory
http://www.securityfocus.com/archive/1/507856/100/0/threaded
http://www.securityfocus.com/bid/36363
http://www.ubuntu.com/usn/USN-839-1
http://www.vupen.com/english/advisories/2009/2810 Vendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/53174
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7211
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7257
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7791
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9191
https://www.redhat.com/archives/fedora-package-announce/2009-October/msg00095.html
https://www.redhat.com/archives/fedora-package-announce/2009-October/msg00098.html
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:a:samba:samba:3.0.12:*:*:*:*:*:*:*
cpe:2.3:a:samba:samba:3.0.13:*:*:*:*:*:*:*
cpe:2.3:a:samba:samba:3.0.14:*:*:*:*:*:*:*
cpe:2.3:a:samba:samba:3.0.14a:*:*:*:*:*:*:*
cpe:2.3:a:samba:samba:3.0.15:*:*:*:*:*:*:*
cpe:2.3:a:samba:samba:3.0.16:*:*:*:*:*:*:*
cpe:2.3:a:samba:samba:3.0.17:*:*:*:*:*:*:*
cpe:2.3:a:samba:samba:3.0.18:*:*:*:*:*:*:*
cpe:2.3:a:samba:samba:3.0.19:*:*:*:*:*:*:*
cpe:2.3:a:samba:samba:3.0.20:*:*:*:*:*:*:*
cpe:2.3:a:samba:samba:3.0.20a:*:*:*:*:*:*:*
cpe:2.3:a:samba:samba:3.0.20b:*:*:*:*:*:*:*
cpe:2.3:a:samba:samba:3.0.21:*:*:*:*:*:*:*
cpe:2.3:a:samba:samba:3.0.21a:*:*:*:*:*:*:*
cpe:2.3:a:samba:samba:3.0.21b:*:*:*:*:*:*:*
cpe:2.3:a:samba:samba:3.0.21c:*:*:*:*:*:*:*
cpe:2.3:a:samba:samba:3.0.22:*:*:*:*:*:*:*
cpe:2.3:a:samba:samba:3.0.23:*:*:*:*:*:*:*
cpe:2.3:a:samba:samba:3.0.23a:*:*:*:*:*:*:*
cpe:2.3:a:samba:samba:3.0.23b:*:*:*:*:*:*:*
cpe:2.3:a:samba:samba:3.0.23c:*:*:*:*:*:*:*
cpe:2.3:a:samba:samba:3.0.23d:*:*:*:*:*:*:*
cpe:2.3:a:samba:samba:3.0.24:*:*:*:*:*:*:*
cpe:2.3:a:samba:samba:3.0.25:*:*:*:*:*:*:*
cpe:2.3:a:samba:samba:3.0.25:pre1:*:*:*:*:*:*
cpe:2.3:a:samba:samba:3.0.25:pre2:*:*:*:*:*:*
cpe:2.3:a:samba:samba:3.0.25:rc1:*:*:*:*:*:*
cpe:2.3:a:samba:samba:3.0.25:rc2:*:*:*:*:*:*
cpe:2.3:a:samba:samba:3.0.25:rc3:*:*:*:*:*:*
cpe:2.3:a:samba:samba:3.0.25a:*:*:*:*:*:*:*
cpe:2.3:a:samba:samba:3.0.25b:*:*:*:*:*:*:*
cpe:2.3:a:samba:samba:3.0.25c:*:*:*:*:*:*:*
cpe:2.3:a:samba:samba:3.0.26:*:*:*:*:*:*:*
cpe:2.3:a:samba:samba:3.0.26a:*:*:*:*:*:*:*
cpe:2.3:a:samba:samba:3.0.27:*:*:*:*:*:*:*
cpe:2.3:a:samba:samba:3.0.27a:*:*:*:*:*:*:*
cpe:2.3:a:samba:samba:3.0.28:*:*:*:*:*:*:*
cpe:2.3:a:samba:samba:3.0.28a:*:*:*:*:*:*:*
cpe:2.3:a:samba:samba:3.0.29:*:*:*:*:*:*:*
cpe:2.3:a:samba:samba:3.0.30:*:*:*:*:*:*:*
cpe:2.3:a:samba:samba:3.0.31:*:*:*:*:*:*:*
cpe:2.3:a:samba:samba:3.0.32:*:*:*:*:*:*:*
cpe:2.3:a:samba:samba:3.0.33:*:*:*:*:*:*:*
cpe:2.3:a:samba:samba:3.0.34:*:*:*:*:*:*:*
cpe:2.3:a:samba:samba:3.0.35:*:*:*:*:*:*:*
cpe:2.3:a:samba:samba:3.0.36:*:*:*:*:*:*:*
cpe:2.3:a:samba:samba:3.2:*:*:*:*:*:*:*
cpe:2.3:a:samba:samba:3.2.0:*:*:*:*:*:*:*
cpe:2.3:a:samba:samba:3.2.1:*:*:*:*:*:*:*
cpe:2.3:a:samba:samba:3.2.2:*:*:*:*:*:*:*
cpe:2.3:a:samba:samba:3.2.3:*:*:*:*:*:*:*
cpe:2.3:a:samba:samba:3.2.4:*:*:*:*:*:*:*
cpe:2.3:a:samba:samba:3.2.5:*:*:*:*:*:*:*
cpe:2.3:a:samba:samba:3.2.6:*:*:*:*:*:*:*
cpe:2.3:a:samba:samba:3.2.7:*:*:*:*:*:*:*
cpe:2.3:a:samba:samba:3.2.8:*:*:*:*:*:*:*
cpe:2.3:a:samba:samba:3.2.9:*:*:*:*:*:*:*
cpe:2.3:a:samba:samba:3.2.10:*:*:*:*:*:*:*
cpe:2.3:a:samba:samba:3.2.11:*:*:*:*:*:*:*
cpe:2.3:a:samba:samba:3.2.12:*:*:*:*:*:*:*
cpe:2.3:a:samba:samba:3.2.13:*:*:*:*:*:*:*
cpe:2.3:a:samba:samba:3.2.14:*:*:*:*:*:*:*
cpe:2.3:a:samba:samba:3.2.15:*:*:*:*:*:*:*
cpe:2.3:a:samba:samba:3.3:*:*:*:*:*:*:*
cpe:2.3:a:samba:samba:3.3.0:*:*:*:*:*:*:*
cpe:2.3:a:samba:samba:3.3.1:*:*:*:*:*:*:*
cpe:2.3:a:samba:samba:3.3.2:*:*:*:*:*:*:*
cpe:2.3:a:samba:samba:3.3.3:*:*:*:*:*:*:*
cpe:2.3:a:samba:samba:3.3.4:*:*:*:*:*:*:*
cpe:2.3:a:samba:samba:3.3.5:*:*:*:*:*:*:*
cpe:2.3:a:samba:samba:3.3.6:*:*:*:*:*:*:*
cpe:2.3:a:samba:samba:3.3.7:*:*:*:*:*:*:*
cpe:2.3:a:samba:samba:3.4:*:*:*:*:*:*:*
cpe:2.3:a:samba:samba:3.4.0:*:*:*:*:*:*:*
cpe:2.3:a:samba:samba:3.4.1:*:*:*:*:*:*:*
OR cpe:2.3:o:apple:mac_os_x:10.5.8:*:*:*:*:*:*:*
cpe:2.3:o:apple:mac_os_x_server:10.5.8:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:o:fedoraproject:fedora:11:*:*:*:*:*:*:*

History

21 Nov 2024, 01:05

Type Values Removed Values Added
References () http://lists.apple.com/archives/security-announce/2009/Sep/msg00004.html - () http://lists.apple.com/archives/security-announce/2009/Sep/msg00004.html -
References () http://lists.opensuse.org/opensuse-security-announce/2009-10/msg00004.html - () http://lists.opensuse.org/opensuse-security-announce/2009-10/msg00004.html -
References () http://marc.info/?l=bugtraq&m=126514298313071&w=2 - () http://marc.info/?l=bugtraq&m=126514298313071&w=2 -
References () http://news.samba.org/releases/3.0.37/ - () http://news.samba.org/releases/3.0.37/ -
References () http://news.samba.org/releases/3.2.15/ - () http://news.samba.org/releases/3.2.15/ -
References () http://news.samba.org/releases/3.3.8/ - () http://news.samba.org/releases/3.3.8/ -
References () http://news.samba.org/releases/3.4.2/ - () http://news.samba.org/releases/3.4.2/ -
References () http://osvdb.org/57955 - () http://osvdb.org/57955 -
References () http://secunia.com/advisories/36701 - Vendor Advisory () http://secunia.com/advisories/36701 - Vendor Advisory
References () http://secunia.com/advisories/36893 - Vendor Advisory () http://secunia.com/advisories/36893 - Vendor Advisory
References () http://secunia.com/advisories/36918 - Vendor Advisory () http://secunia.com/advisories/36918 - Vendor Advisory
References () http://secunia.com/advisories/36937 - Vendor Advisory () http://secunia.com/advisories/36937 - Vendor Advisory
References () http://secunia.com/advisories/36953 - Vendor Advisory () http://secunia.com/advisories/36953 - Vendor Advisory
References () http://secunia.com/advisories/37428 - Vendor Advisory () http://secunia.com/advisories/37428 - Vendor Advisory
References () http://slackware.com/security/viewer.php?l=slackware-security&y=2009&m=slackware-security.561439 - () http://slackware.com/security/viewer.php?l=slackware-security&y=2009&m=slackware-security.561439 -
References () http://sunsolve.sun.com/search/document.do?assetkey=1-77-1021111.1-1 - () http://sunsolve.sun.com/search/document.do?assetkey=1-77-1021111.1-1 -
References () http://support.apple.com/kb/HT3865 - Vendor Advisory () http://support.apple.com/kb/HT3865 - Vendor Advisory
References () http://wiki.rpath.com/Advisories:rPSA-2009-0145 - () http://wiki.rpath.com/Advisories:rPSA-2009-0145 -
References () http://www.samba.org/samba/security/CVE-2009-2813.html - Vendor Advisory () http://www.samba.org/samba/security/CVE-2009-2813.html - Vendor Advisory
References () http://www.securityfocus.com/archive/1/507856/100/0/threaded - () http://www.securityfocus.com/archive/1/507856/100/0/threaded -
References () http://www.securityfocus.com/bid/36363 - () http://www.securityfocus.com/bid/36363 -
References () http://www.ubuntu.com/usn/USN-839-1 - () http://www.ubuntu.com/usn/USN-839-1 -
References () http://www.vupen.com/english/advisories/2009/2810 - Vendor Advisory () http://www.vupen.com/english/advisories/2009/2810 - Vendor Advisory
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/53174 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/53174 -
References () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7211 - () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7211 -
References () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7257 - () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7257 -
References () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7791 - () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7791 -
References () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9191 - () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9191 -
References () https://www.redhat.com/archives/fedora-package-announce/2009-October/msg00095.html - () https://www.redhat.com/archives/fedora-package-announce/2009-October/msg00095.html -
References () https://www.redhat.com/archives/fedora-package-announce/2009-October/msg00098.html - () https://www.redhat.com/archives/fedora-package-announce/2009-October/msg00098.html -

Information

Published : 2009-09-14 16:30

Updated : 2024-11-21 01:05


NVD link : CVE-2009-2813

Mitre link : CVE-2009-2813

CVE.ORG link : CVE-2009-2813


JSON object : View

Products Affected

apple

  • mac_os_x
  • mac_os_x_server

samba

  • samba

fedoraproject

  • fedora
CWE
CWE-264

Permissions, Privileges, and Access Controls